99.7% of firms have AI access policies, yet 87% saw agents reach sensitive data

daniel_tenuo · reddit · 2026-10-09

A Delinea survey found 99.7% of respondents have formal AI access policies, yet 87% still reported an AI tool or agent reaching data it shouldn't. The author argues written policy rarely becomes a hard runtime boundary: a prompt telling an agent to work only on customer 4471 means nothing if its service token opens every customer. The post explores where the enforcement gap comes from, why subagents make it worse, and why scope must be enforced before an action runs.

Original post →

More from coding & agent

coding & agent channel →